Apple

iPhone OS

3904 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.08%
  • Veröffentlicht 17.08.2015 00:00:39
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking.

  • EPSS 2.1%
  • Veröffentlicht 17.08.2015 00:00:38
  • Zuletzt bearbeitet 12.04.2025 10:46:40

FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-380...

  • EPSS 2.81%
  • Veröffentlicht 17.08.2015 00:00:36
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761.

  • EPSS 0.43%
  • Veröffentlicht 17.08.2015 00:00:32
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink.

  • EPSS 0.3%
  • Veröffentlicht 17.08.2015 00:00:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.

  • EPSS 0.08%
  • Veröffentlicht 17.08.2015 00:00:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.

  • EPSS 0.23%
  • Veröffentlicht 17.08.2015 00:00:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.

  • EPSS 2.37%
  • Veröffentlicht 17.08.2015 00:00:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.

  • EPSS 0.05%
  • Veröffentlicht 17.08.2015 00:00:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.

  • EPSS 0.06%
  • Veröffentlicht 17.08.2015 00:00:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.